Show filters
36 Total Results
Displaying 1-10 of 36
Sort by:
Attacker Value
Unknown

CVE-2025-22332

Disclosure Date: January 31, 2025 (last updated January 31, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bryan Shanaver @ fiftyandfifty.org CloudFlare(R) Cache Purge allows Reflected XSS. This issue affects CloudFlare(R) Cache Purge: from n/a through 1.2.
0
Attacker Value
Unknown

CVE-2024-50583

Disclosure Date: October 25, 2024 (last updated October 25, 2024)
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.
0
Attacker Value
Unknown

CVE-2024-40618

Disclosure Date: July 11, 2024 (last updated July 11, 2024)
Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.
0
Attacker Value
Unknown

CVE-2024-28216

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
0
Attacker Value
Unknown

CVE-2024-28215

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
0
Attacker Value
Unknown

CVE-2024-28214

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.
0
Attacker Value
Unknown

CVE-2024-28213

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.
0
Attacker Value
Unknown

CVE-2024-28212

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.
0
Attacker Value
Unknown

CVE-2024-28211

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.
0
Attacker Value
Unknown

CVE-2023-25632

Disclosure Date: November 27, 2023 (last updated December 02, 2023)
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.